| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2039-Jul-15 21:04:31 |
| Detected languages |
English - United States
|
| Debug artifacts |
notepad.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Notepad |
| FileVersion | 10.0.26100.8328 (WinBuild.160101.0800) |
| InternalName | Notepad |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | NOTEPAD.EXE |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.26100.8328 |
| Info | Matching compiler(s): | Microsoft Visual C++ 8.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: fothk |
| Malicious | The PE contains functions mostly used by malware. |
Can access the registry:
|
| Safe | VirusTotal score: 0/71 (Scanned on 2026-05-20 15:16:44) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0xf8 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2039-Jul-15 21:04:31 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x28000 |
| SizeOfInitializedData | 0x31000 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000019C0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x1000 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x5a000 |
| SizeOfHeaders | 0x1000 |
| Checksum | 0x5e060 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x80000 |
| SizeofStackCommit | 0x11000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| GDI32.dll |
SetMapMode
SetViewportExtEx SetWindowExtEx LPtoDP SetBkMode GetTextMetricsW TextOutW AbortDoc EndDoc SetAbortProc StartDocW StartPage CreateDCW EnumFontsW GetTextFaceW GetDeviceCaps DeleteDC DeleteObject SetBkColor CreateSolidBrush GetTextExtentPoint32W SelectObject CreateCompatibleDC EndPage CreateFontIndirectW |
|---|---|
| USER32.dll |
PostQuitMessage
BeginPaint EndPaint FillRect DrawTextW DrawFocusRect DefWindowProcW TrackMouseEvent InvalidateRect DestroyIcon SetThreadDpiAwarenessContext DialogBoxParamW LoadIconW GetFocus MessageBoxW ShowWindow SetCursor SetActiveWindow EnableMenuItem IsIconic SetFocus MessageBeep GetForegroundWindow GetDlgCtrlID SetWindowPos RedrawWindow GetKeyboardLayout CharNextW SetWinEventHook GetMessageW TranslateAcceleratorW IsDialogMessageW TranslateMessage DispatchMessageW UnhookWinEvent SetWindowTextW GetMenu GetSubMenu OpenClipboard IsClipboardFormatAvailable CloseClipboard CheckMenuItem SetDlgItemTextW GetDlgItemTextW EndDialog SendDlgItemMessageW SetScrollPos UpdateWindow GetWindowPlacement SetWindowPlacement CharUpperW GetSystemMenu LoadAcceleratorsW SetWindowLongW MonitorFromWindow RegisterWindowMessageW LoadCursorW LoadImageW RegisterClassExW GetWindowLongW PeekMessageW GetWindowTextW EnableWindow CreateDialogParamW DrawTextExW IsWindow CreateDialogIndirectParamW GetPropW SetPropW GetDlgItem RemovePropW CheckDlgButton CheckRadioButton IsDlgButtonChecked NotifyWinEvent CreateWindowExW GetWindowTextLengthW GetClientRect DestroyWindow GetDpiForWindow SystemParametersInfoForDpi SendMessageW MoveWindow GetDC LoadStringW PostMessageW ReleaseDC |
| api-ms-win-crt-string-l1-1-0.dll |
wcscmp
wcsnlen memset |
| api-ms-win-crt-runtime-l1-1-0.dll |
_c_exit
_initterm_e _initterm _register_thread_local_exe_atexit_callback |
| api-ms-win-crt-private-l1-1-0.dll |
_o__get_wide_winmain_command_line
_o__initialize_onexit_table _o__initialize_wide_environment _o__invalid_parameter_noinfo _o__purecall _o__register_onexit_function _o__seh_filter_exe _o__set_app_type _o__set_fmode _o__set_new_mode _o__wcsicmp _o__wtol _o_exit _o_free _o_iswdigit _o_malloc _o_terminate __CxxFrameHandler3 __current_exception __current_exception_context _CxxThrowException _o__crt_atexit _o___stdio_common_vswprintf _o__configure_wide_argv _o___std_exception_destroy _o___std_exception_copy _o__configthreadlocale _o___p__commode _o__exit _o__cexit _o__callnewh _o__beginthreadex _o__errno wcsrchr wcschr __C_specific_handler memcmp memcpy memmove |
| api-ms-win-core-libraryloader-l1-2-0.dll |
LockResource
GetModuleHandleExW FindResourceExW LoadResource GetModuleHandleA GetModuleFileNameA FreeLibrary GetProcAddress GetModuleHandleW GetModuleFileNameW |
| api-ms-win-core-synch-l1-1-0.dll |
LeaveCriticalSection
InitializeCriticalSectionEx WaitForSingleObject ReleaseSemaphore ReleaseSRWLockExclusive EnterCriticalSection SetEvent CreateEventExW AcquireSRWLockExclusive ReleaseMutex WaitForSingleObjectEx DeleteCriticalSection AcquireSRWLockShared CreateMutexExW OpenSemaphoreW ReleaseSRWLockShared CreateSemaphoreExW |
| api-ms-win-core-heap-l1-1-0.dll |
GetProcessHeap
HeapAlloc HeapSetInformation HeapFree |
| api-ms-win-core-errorhandling-l1-1-0.dll |
UnhandledExceptionFilter
SetUnhandledExceptionFilter RaiseException GetLastError SetLastError |
| api-ms-win-core-threadpool-l1-2-0.dll |
CloseThreadpoolTimer
WaitForThreadpoolTimerCallbacks CreateThreadpoolTimer SetThreadpoolTimer |
| api-ms-win-core-processthreads-l1-1-0.dll |
GetCurrentProcess
OpenProcessToken CreateProcessW TerminateProcess GetCurrentThreadId GetStartupInfoW GetCurrentProcessId |
| api-ms-win-core-localization-l1-2-0.dll |
FormatMessageW
FindNLSString GetLocaleInfoW GetACP |
| api-ms-win-core-debug-l1-1-0.dll |
IsDebuggerPresent
OutputDebugStringW DebugBreak |
| api-ms-win-core-handle-l1-1-0.dll |
CloseHandle
|
| api-ms-win-core-com-l1-1-0.dll |
CoTaskMemFree
CoCreateInstance CoInitializeEx PropVariantClear CoUninitialize CoWaitForMultipleHandles CoCreateGuid CoTaskMemAlloc CoCreateFreeThreadedMarshaler |
| api-ms-win-core-registry-l1-1-1.dll |
RegSetKeyValueW
|
| api-ms-win-core-largeinteger-l1-1-0.dll |
MulDiv
|
| api-ms-win-core-shlwapi-legacy-l1-1-0.dll |
PathFindExtensionW
PathIsFileSpecW PathFileExistsW |
| api-ms-win-core-winrt-string-l1-1-0.dll |
WindowsDeleteString
WindowsCreateString WindowsCreateStringReference WindowsGetStringRawBuffer |
| api-ms-win-core-registry-l1-1-0.dll |
RegQueryValueExW
RegGetValueW RegSetValueExW RegEnumValueW RegQueryInfoKeyW RegCreateKeyExW RegCloseKey RegOpenKeyExW RegDeleteKeyExW |
| api-ms-win-core-winrt-l1-1-0.dll |
RoGetActivationFactory
|
| api-ms-win-core-heap-l2-1-0.dll |
LocalUnlock
LocalFree LocalLock GlobalAlloc GlobalFree LocalAlloc LocalReAlloc |
| api-ms-win-core-file-l1-1-0.dll |
DeleteFileW
GetFileAttributesW SetEndOfFile GetFileAttributesExW GetFileInformationByHandle FindClose FindFirstFileW CreateFileW ReadFile GetDiskFreeSpaceExW GetFullPathNameW CreateDirectoryW WriteFile |
| api-ms-win-shcore-obsolete-l1-1-0.dll |
SHStrDupW
|
| api-ms-win-security-base-l1-1-0.dll |
GetTokenInformation
|
| api-ms-win-core-processenvironment-l1-1-0.dll |
GetCurrentDirectoryW
GetCommandLineW SetCurrentDirectoryW |
| api-ms-win-core-string-l1-1-0.dll |
FoldStringW
WideCharToMultiByte CompareStringOrdinal MultiByteToWideChar |
| api-ms-win-core-psapi-l1-1-0.dll |
K32GetModuleFileNameExW
|
| api-ms-win-core-localization-obsolete-l1-2-0.dll |
GetUserDefaultUILanguage
|
| api-ms-win-core-sysinfo-l1-1-0.dll |
GetLocalTime
GetSystemTimeAsFileTime |
| api-ms-win-core-datetime-l1-1-0.dll |
GetDateFormatW
GetTimeFormatW |
| api-ms-win-shcore-path-l1-1-0.dll |
#170
|
| api-ms-win-core-memory-l1-1-0.dll |
MapViewOfFile
CreateFileMappingW UnmapViewOfFile |
| api-ms-win-core-registry-l2-1-0.dll |
RegCreateKeyW
|
| api-ms-win-core-heap-obsolete-l1-1-0.dll |
LocalSize
GlobalLock GlobalUnlock |
| api-ms-win-shcore-scaling-l1-1-1.dll |
GetDpiForMonitor
|
| api-ms-win-core-string-obsolete-l1-1-0.dll |
lstrcmpiW
|
| api-ms-win-core-windowserrorreporting-l1-1-3.dll |
RegisterApplicationRestart
|
| api-ms-win-eventing-provider-l1-1-0.dll |
EventRegister
EventUnregister EventWriteTransfer EventSetInformation |
| api-ms-win-base-util-l1-1-0.dll |
IsTextUnicode
|
| api-ms-win-core-libraryloader-l1-2-1.dll |
FindResourceW
|
| api-ms-win-core-rtlsupport-l1-1-0.dll |
RtlVirtualUnwind
RtlLookupFunctionEntry RtlCaptureContext |
| api-ms-win-core-processthreads-l1-1-1.dll |
IsProcessorFeaturePresent
GetProcessMitigationPolicy |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceCounter
|
| api-ms-win-core-interlocked-l1-1-0.dll |
InitializeSListHead
|
| api-ms-win-core-winrt-error-l1-1-0.dll |
SetRestrictedErrorInfo
|
| api-ms-win-core-winrt-error-l1-1-1.dll |
RoGetMatchingRestrictedErrorInfo
|
| COMCTL32.dll |
ImageList_Create
ImageList_SetBkColor #381 ImageList_ReplaceIcon #410 ImageList_Draw ImageList_GetIconSize #413 ImageList_Destroy #345 CreateStatusWindowW |
| api-ms-win-core-delayload-l1-1-1.dll |
ResolveDelayLoadedAPI
|
| api-ms-win-core-delayload-l1-1-0.dll |
DelayLoadFailureHook
|
| ADVAPI32.dll (delay-loaded) |
DecryptFileW
DuplicateEncryptionInfoFile |
| Attributes | 0x1 |
|---|---|
| Name | ADVAPI32.dll |
| ModuleHandle | 0x352a8 |
| DelayImportAddressTable | 0x39000 |
| DelayImportNameTable | 0x304a8 |
| BoundDelayImportTable | 0x30798 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.26100.8328 |
| ProductVersion | 10.0.26100.8328 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Notepad |
| FileVersion (#2) | 10.0.26100.8328 (WinBuild.160101.0800) |
| InternalName | Notepad |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | NOTEPAD.EXE |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.26100.8328 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2039-Jul-15 21:04:31 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x2ed80 |
| PointerToRawData | 0x2ed80 |
| Referenced File | notepad.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2039-Jul-15 21:04:31 |
| Version | 0.0 |
| SizeofData | 1256 |
| AddressOfRawData | 0x2eda4 |
| PointerToRawData | 0x2eda4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2039-Jul-15 21:04:31 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x2f2b4 |
| PointerToRawData | 0x2f2b4 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2039-Jul-15 21:04:31 |
| Version | 0.0 |
| SizeofData | 4 |
| AddressOfRawData | 0x2f2d8 |
| PointerToRawData | 0x2f2d8 |
| Size | 0x148 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140034400 |
| GuardCFCheckFunctionPointer | 5368882240 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0xa4531774 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 94 |
| Unmarked objects (#2) | 1 |
| C objects (33145) | 11 |
| ASM objects (33145) | 5 |
| C++ objects (33145) | 31 |
| Imports (33145) | 7 |
| Total imports | 1380 |
| C objects (LTCG) (33145) | 28 |
| 253 (33145) | 1 |
| Resource objects (33145) | 1 |
| Linker (33145) | 1 |
No comments yet.